From 2eb99915cf14409c1b4dd149f7d270ae49d34272 Mon Sep 17 00:00:00 2001 From: Prabir Pradhan Date: Wed, 31 May 2023 20:38:50 +0000 Subject: [PATCH] Ensure embedded window's channel is not disposed before being duped If the InputChannel is created inside a critical section, but then duped to another channel after the lock is released, it's possible the channel could be disposed (e.g. because window is removed) before the duplication happens. To prevent this, dup the InputChannel in the same critical section as where it was created. Bug: 283314325 Test: Presubmit Change-Id: I00dd3e54240512a6d2ddfe7ec40a6c4f14d837fc --- .../android/server/wm/EmbeddedWindowController.java | 5 +++-- .../com/android/server/wm/WindowManagerService.java | 10 ++++------ 2 files changed, 7 insertions(+), 8 deletions(-) diff --git a/services/core/java/com/android/server/wm/EmbeddedWindowController.java b/services/core/java/com/android/server/wm/EmbeddedWindowController.java index 44d67687e2604..98027bbed37f1 100644 --- a/services/core/java/com/android/server/wm/EmbeddedWindowController.java +++ b/services/core/java/com/android/server/wm/EmbeddedWindowController.java @@ -23,6 +23,7 @@ import static com.android.server.wm.WindowManagerDebugConfig.TAG_WITH_CLASS_NAME import static com.android.server.wm.WindowManagerDebugConfig.TAG_WM; import static com.android.server.wm.WindowStateProto.IDENTIFIER; +import android.annotation.NonNull; import android.annotation.Nullable; import android.os.IBinder; import android.os.RemoteException; @@ -217,10 +218,10 @@ class EmbeddedWindowController { mHostWindowState.mInputWindowHandle.getInputApplicationHandle()); } - InputChannel openInputChannel() { + void openInputChannel(@NonNull InputChannel outInputChannel) { final String name = toString(); mInputChannel = mWmService.mInputManager.createInputChannel(name); - return mInputChannel; + mInputChannel.copyTo(outInputChannel); } void onRemoved() { diff --git a/services/core/java/com/android/server/wm/WindowManagerService.java b/services/core/java/com/android/server/wm/WindowManagerService.java index 9c636ea0ae85c..d7bc51b2ecf59 100644 --- a/services/core/java/com/android/server/wm/WindowManagerService.java +++ b/services/core/java/com/android/server/wm/WindowManagerService.java @@ -8738,24 +8738,22 @@ public class WindowManagerService extends IWindowManager.Stub final int sanitizedType = sanitizeWindowType(session, displayId, windowToken, type); final InputApplicationHandle applicationHandle; final String name; - final InputChannel clientChannel; + Objects.requireNonNull(outInputChannel); synchronized (mGlobalLock) { EmbeddedWindowController.EmbeddedWindow win = new EmbeddedWindowController.EmbeddedWindow(session, this, window, mInputToWindowMap.get(hostInputToken), callingUid, callingPid, sanitizedType, displayId, focusGrantToken, inputHandleName, (flags & FLAG_NOT_FOCUSABLE) == 0); - clientChannel = win.openInputChannel(); - mEmbeddedWindowController.add(clientChannel.getToken(), win); + win.openInputChannel(outInputChannel); + mEmbeddedWindowController.add(outInputChannel.getToken(), win); applicationHandle = win.getApplicationHandle(); name = win.toString(); } - updateInputChannel(clientChannel.getToken(), callingUid, callingPid, displayId, surface, + updateInputChannel(outInputChannel.getToken(), callingUid, callingPid, displayId, surface, name, applicationHandle, flags, privateFlags, inputFeatures, sanitizedType, null /* region */, window); - - clientChannel.copyTo(outInputChannel); } boolean transferEmbeddedTouchFocusToHost(IWindow embeddedWindow) {